LFCS — Linux Foundation System Administrator
Permission Bits, umask and the ACL Mask
Goal
You set up octal and symbolic modes, umask, special bits, and ACLs with masks in turn inside one directory, and see their interaction with your own eyes.
Why it matters
A permission problem starts with "why doesn't it work" and usually ends with chmod 777. The reason that habit gets caught in an audit is simple — what was needed was an exception for one person, but the door was opened to everyone. The judgment to use an ACL instead of creating a new group when a requirement arises that the three slots (owner, group, other) cannot express, and the judgment to unify the group with setgid when several people pile files into the same directory, are the core of this domain. The mask is especially important. Even after you grant an ACL exactly, if someone later runs chmod once, the mask is recalculated and that ACL is silently disabled. You have to be able to read the #effective: marker of getfacl to recognize this situation in 5 seconds.
Steps
- Create the directory
/root/lfcs-perm/, and create a grouplfcsteamand userslfcsoneandlfcstwo. Both users must havelfcsteamas a supplementary group (the primary group is each one's own private group). - Create
/root/lfcs-perm/notes.txtand set its permissions to 640 and its group tolfcsteam. - Put any content in
/root/lfcs-perm/run.sh, and use symbolic mode to set its permissions to 750 and its group tolfcsteam. - In a shell where umask is changed to
0027, newly create the file/root/lfcs-perm/umask-demo/newfileand the directory/root/lfcs-perm/umask-demo/newdir. Then write three lines in/root/lfcs-perm/umask.txt:umask=0027,file=<새 파일의 권한>, anddir=<새 디렉터리의 권한>(file= followed by the new file's permissions, and dir= followed by the new directory's permissions). - Create
/root/lfcs-perm/probeowned by root with permissions4755, and create the directory/root/lfcs-perm/tools/with1777. - Create
/root/lfcs-perm/shared/with grouplfcsteamand permissions2770, and then createhandoff.txtinside it. The file's group must becomelfcsteamby inheritance. - Give
handoff.txtan ACL ofrw-forlfcsoneandr--forlfcstwo, and give theshared/directory a default ACL ofrwxfor thelfcsteamgroup. - Lower the ACL mask of
handoff.txttor--, and write one line in/root/lfcs-perm/mask.txt:lfcsone_effective=<마스크 적용 후 lfcsone 의 실효 권한>(lfcsone_effective= followed by lfcsone's effective permissions after the mask is applied).
Notes
- A special bit is the leading digit of four octal digits. setuid is 4, setgid is 2, sticky is 1.
- Step 6 is all about order. A file created before you set the bit does not inherit the group.
getfacladds#effective:only when the mask actually trims the real permissions.- A common mistake: if you run
chmodafter giving the ACL, the group bits are interpreted as the mask and the ACL is disabled.
Prepare groups and users for collaboration
Create the directory /root/lfcs-perm/, and create a group lfcsteam and users lfcsone and lfcstwo. Both users must have lfcsteam as a supplementary group (the primary group is each one's own private group).
Both users must have the team group as a supplementary group. If you make the team group their primary group as well, the inheritance experiment in the later steps loses its meaning.
Octal mode and group ownership
Create /root/lfcs-perm/notes.txt and set its permissions to 640 and its group to lfcsteam.
Permissions and group are different commands. 640 means read and write for the owner, read for the group, and nothing for others.
Setting permissions with symbolic mode
Put any content in /root/lfcs-perm/run.sh, and use symbolic mode to set its permissions to 750 and its group to lfcsteam.
Symbolic mode combines a target (u/g/o/a), an operator (+/-/=), and permissions (r/w/x). The equals sign erases the rest and leaves only the specified value.
How umask trims the default permissions
In a shell where umask is changed to 0027, newly create the file /root/lfcs-perm/umask-demo/newfile and the directory /root/lfcs-perm/umask-demo/newdir. Then write three lines in /root/lfcs-perm/umask.txt: umask=0027, file=<새 파일의 권한>, and dir=<새 디렉터리의 권한> (file= followed by the new file's permissions, and dir= followed by the new directory's permissions).
The base value for files is 666 and for directories is 777, and the umask bits are subtracted from there. Do not fix it with chmod afterward; create them fresh in the shell where you changed umask.
The setuid and sticky bits
Create /root/lfcs-perm/probe owned by root with permissions 4755, and create the directory /root/lfcs-perm/tools/ with 1777.
A special bit is the leading digit of four octal digits. setuid is 4, setgid is 2, and sticky is 1. For setuid, who the owner is is the key.
A setgid collaboration directory
Create /root/lfcs-perm/shared/ with group lfcsteam and permissions 2770, and then create handoff.txt inside it. The file's group must become lfcsteam by inheritance.
Order matters. Inheritance happens only if you set the bit on the directory and match the group first, and then create the file inside.
Named-user ACL and default ACL
Give handoff.txt an ACL of rw- for lfcsone and r-- for lfcstwo, and give the shared/ directory a default ACL of rwx for the lfcsteam group.
On the file you put individual user entries, and on the directory you put an entry to pass on to files created from now on. The latter needs a separate flag.
The mask trims the effective permissions
Lower the ACL mask of handoff.txt to r--, and write one line in /root/lfcs-perm/mask.txt: lfcsone_effective=<마스크 적용 후 lfcsone 의 실효 권한> (lfcsone_effective= followed by lfcsone's effective permissions after the mask is applied).
The mask is the upper limit for all entries except the owner and other. There is an entry notation that specifies the mask by itself, and once you lower it, getfacl shows the effective permissions alongside.